Subway Surfers Official
afanpbdmlbfmjbfofhbaaafcpmjfgfem
Risk Score
4.71
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack and install URL hijack are active monetization/tracking patterns.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- External JS loaded from gameograf.com enables remote code update without store review.
- No developer name on listing; manifest uses placeholder strings (__MSG_appName__).
- Verified publisher discount limited: generic privacy policy points to non-developer domain.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; uninstall_url_target is null but flag is true.
- install_url_hijack crx onInstalled opens external URL; install_url_target is null but flag is true.
- privacy_policy_generic store Policy URL is Google's own account policy; fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true.
- js_external_hosts crx Extension references gameograf.com as external JS host — remote code capability outside CWS review.
- no_developer_name store developer_name is empty string; manifest uses __MSG_appName__ placeholder.
- verified_publisher store Listing carries verified_publisher=true, but discount capped due to generic unscoped privacy policy.
- low_rating store Rating 3.4; install count only 6,000 for an 'Official' game extension claim.
- csp_absent crx content_security_policy is null; csp_present=false on MV3 extension with external JS host.
Permissions Breakdown
- uninstall_url_hijack high Extension sets an uninstall URL to a third-party destination, a monetization/tracking signal.
- install_url_hijack high Extension opens a URL on install via onInstalled, a known traffic-monetization pattern.
- js_external_hosts (gameograf.com) medium Extension loads JS from developer-controlled external host; remote code execution risk.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality1.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 09:41
Listing SHA
5ee7cfb998bf…
Force block
— not fired
Score recovered
no
Elapsed
—